Information disclosure in APM Clients and BIG-IP APM - CVE-2021-23002

 

Information disclosure in APM Clients and BIG-IP APM - CVE-2021-23002

Published: March 22, 2021


Vulnerability identifier: #VU51601
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23002
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to the session ID is visible in the arguments of the f5vpn.exe command when VPN is launched from the browser on a Windows system. A remote administrator on the local network can view the session ID.


Affected software

APM Clients
BIG-IP APM

How to mitigate CVE-2021-23002

Install updates from vendor's website.

APM Clients - addressed in versions 7.1.8.5, 7.1.9.8, 7.2.1.1
BIG-IP APM - addressed in versions 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1

External References

Related Security Bulletins